The scam text about the missed package. The urgent email from your "bank." The voice on the phone that sounds exactly like your grandson. These are not new tricks, but something has changed: artificial intelligence is now doing the heavy lifting for scammers, and the results are getting harder to spot.
This week's cybersecurity news made the trend official. The World Economic Forum's latest roundup describes AI as an accelerant for cybercrime, with hackers using it to find software vulnerabilities faster and write matching malware to exploit them. Verizon's 2026 Data Breach Investigations Report found that nearly a third of breaches now start with software vulnerabilities, overtaking stolen passwords as the main way attackers get in. AI has not just made scams more convincing. It has made the entire attack pipeline faster, cheaper, and harder to outrun.
The good news is that the fundamentals of defense have not changed. But the bar for "looks legitimate" has moved, so your habits need an upgrade. Here is what scammers can do now, which old red flags still work, and the new defenses worth adopting.
What AI changed for scammers
It used to take real effort to run a convincing scam. Someone had to write the phishing email, and the broken English was often the tell. Someone had to make the phone call, which limited how many victims one scammer could reach. AI removed both bottlenecks.
enerative AI now writes flawless phishing emails in any language, personalized with details scraped from social media and data breaches. Your name, your employer, the conference you attended last month: all of it can be woven into a message that reads like it came from a colleague. Voice cloning needs only a few seconds of audio, easily pulled from a voicemail greeting or a social media video, to impersonate a family member in distress. AI-generated images and video, covered in our earlier guide to spotting fakes, add visual "proof" to investment scams and fake news.
Scale changed too. Where a scammer once manually targeted dozens of people, AI lets one operator run thousands of personalized attacks at once, testing which messages get clicks and refining the approach automatically. And on the technical side, AI helps attackers scan for software vulnerabilities and generate exploits quickly, which is why keeping your devices updated matters more than ever.
The new scammer playbook
Knowing the current plays helps you recognize them. The package delivery text remains a classic, now written in perfect English with a link to a convincing fake tracking page designed to steal your payment details. Toll road scams, often impersonating E-ZPass or similar services, threaten fines for unpaid tolls you never owed. Bank fraud alerts arrive by text claiming suspicious activity, urging you to call a number that reaches the scammers, not your bank.
Then there are the AI-native plays. The "wrong number" text that blossoms into a friendly conversation is often the opening move of a pig butchering scam, a long con that builds trust over weeks before introducing a fake investment opportunity. Voice cloning powers the grandparent scam 2.0: a call from a "loved one" in trouble, with AI filling in the voice and urgency doing the rest. Job offer scams dangle remote work with generous pay, then ask you to pay for "equipment" or deposit fraudulent checks. And fake invoice emails targeting small businesses now mimic real vendors with alarming accuracy, sometimes even continuing genuine email threads the attackers have compromised.
The red flags that still work
Here is the reassuring part: the anatomy of a scam has not changed, even as the production values improved. Every scam still needs you to act quickly, without thinking, in a way you normally would not. That means the classic tells still catch most of them.
Urgency is the biggest one. "Your account will be suspended in 24 hours." "Pay now or face arrest." "Grandma, please don't tell Mom." Legitimate organizations do not operate this way. They send notices, they give you time, and they never threaten you into immediate action over text.
Next, check the ask. Is the message asking you to click a link, call a number, download something, or send money or gift cards? Real companies do not ask for passwords, verification codes, or payment via text. No legitimate business accepts gift cards or cryptocurrency as a way to settle a fine or a bill. That payment method alone is proof of a scam.
Then inspect the sender. Scam texts come from random long numbers or email addresses, not short codes. Email addresses may look close to the real thing but with subtle changes: a zero instead of an O, an extra letter, a different domain. On a phone call, remember that caller ID can be faked in seconds. And for any voice that claims to be family, have a family code word. It sounds old fashioned. It works perfectly against voice cloning.
New defenses worth adopting
The old advice, don't click suspicious links, still holds. But AI-era scams call for a few upgrades to your routine.
First, make "go direct" your reflex. Never use the link, number, or QR code in a suspicious message. If the text claims to be from your bank, open your banking app yourself or call the number on your card. If it is a package, open the retailer's app or site directly. This single habit defeats nearly every impersonation scam, because the scammer's power lives entirely ide the message they sent you.
Second, slow down on purpose. Scammers weaponize urgency because rushed people do not verify. Build a personal rule: any message demanding immediate action gets a ten-minute pause. In those ten minutes, verify through a separate channel. Call the person back on a known number. Check the official website. Ask someone you trust.
Third, lock down the accounts that matter most. Enable two-factor authentication everywhere it is offered, and consider passkeys, which we covered in a recent guide, for your most important accounts. A scammer who steals your password still cannot get in without that second factor. Keep your phone and computer updated, since AI-assisted attackers are exploiting software flaws faster than before, and updates are how those holes get closed.
Fourth, shrink your attack surface. The personal details that make AI scams convincing come from somewhere: social media posts, data breaches, public records. Set social profiles to private, remove your phone number and birthday from public bios, and be stingy with quizzes and forms that harvest personal details. Consider a Google Alert on your own name so you know what is out there.
What to do when a scam arrives
Do not engage. Do not click the link, do not reply, and do not call the number. Even replying STOP can confirm to scammers that your number is active, so for clearly fraudulent texts, delete and report instead. On iPhone and Android you can report spam texts directly, and in the US you can forward them to 7726, which spells SPAM. For phishing emails, forward them to reportphishing@apwg.org and report them to the FTC at reportfraud.ftc.gov.
If the scam impersonates a company, consider telling that company too. Banks, delivery services, and toll agencies all have fraud reporting pages, and your report helps them warn others.
What to do if you already fell for one
Act fast and do not be embarrassed. These scams fool smart, careful people every day; that is the entire point of this article. If you clicked a link and entered credentials, change that password immediately from a device you trust, and change it anywhere else you reused it. Turn on two-factor authentication if it was not on. If you shared financial details, call your bank or card issuer right away using the number on your card, not any number from the scam. They can freeze the account, reverse charges, and watch for fraud.
If you sent money, contact the payment service immediately. Wire transfers and cryptocurrency are very hard to recover, but gift card companies and payment apps sometimes can intervene if you act within hours. File a report with the FTC and your local police; you may need the report number for your bank. And if you gave away personal information like your Social Security number, consider freezing your credit with the three major bureaus. It is free, it takes a few minutes each, and it stops new accounts from being opened in your name.
The bottom line
AI made scammers faster, more convincing, and able to target thousands of people at once. It did not make them invincible. Every scam still runs on urgency, impersonation, and a request you would question if you slowed down. Your defenses are habits, not software: go direct instead of clicking, pause before acting, lock your accounts with two-factor or passkeys, keep devices updated, and never pay a stranger in gift cards. The technology changed. The con is the same one it has always been. And now you know exactly how it works.

